Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Design] letting traffic flow through a SG by default

From: D. Hugh Redelmeier <hugh(at)mimosa.com>
Date: Wed Mar 12 2003 - 21:38:24 EST


-----BEGIN PGP SIGNED MESSAGE-----
| From: D. Hugh Redelmeier <hugh@mimosa.com>

|     conn packetdefault
| 	    leftsubnet=0.0.0.0/0
| 	    also=private-or-clear

Oops: I meant:

conn packetdefault

	type=tunnel
    	left=%defaultroute
	# leftid is affected by myid=
	leftsubnet=0.0.0.0/0
	right=%opportunistic
	failureshunt=passthrough
	keyingtries=3
	ikelifetime=1h
	keylife=1h
	rekey=no
	auto=route

This must be a 0.0.0.0/0 -> 0.0.0.0/0 eroute, so this cannot be a policy group. Otherwise the characteristics are similar to private-or-clear.

(Thanks, Claudia for pointing this out.)

Hugh Redelmeier
hugh@mimosa.com voice: +1 416 482-8253

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPm/vI8FAuQPManGZAQEW9gQAldN71rgYfvJ127AnEipFnH4CnWrYOuQa Yzcxm2uqFXpBvYljQErYCib2nBijMMErByQu7rFgEBi5u/VEJRetYHlhtSfWZF/T 8Z+rl5stFvZx4x0MMCfWN2tJMOWDgNktEvovl7pRVEr6Q3/xpp5sUQmq/XGoZdAi 3Bu7k6q5qzY=
=G3LL
-----END PGP SIGNATURE-----



Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design Received on Thu Mar 13 02:31:39 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library